iam-role-abuse

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A complete SSRF-to-RCE exploit chain on AWS Elastic Beanstalk that leverages the EC2 metadata service to extract IAM credentials, then uses those credentials to upload a PHP web shell to an accessible S3 bucket for remote code execution. The attack demonstrates how weak IAM policies can enable escalation from SSRF to full system compromise.

Youssef A. Mohamed GeneralEG CESPPA Squnity Synack AWS Elastic Beanstalk AWS Systems Manager AWS CLI 169.254.169.254 aws-elasticbeanstalk-ec2-role AWSElasticBeanstalkWebTier
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details